top of page
fnlogo.png

U.S. Regulators Clarify What Banks Can Tell Customers About Suspicious Activity Reports

1 day ago
6 min read

Federal regulators have clarified that SAR confidentiality does not prevent banks and credit unions from discussing suspicious transactions, potential fraud and certain account restrictions with customers—as long as the existence of a Suspicious Activity Report is not disclosed.


U.S. Regulators Clarify What Banks Can Tell Customers About Suspicious Activity Reports

U.S. financial regulators have provided banks and credit unions with important clarification on how they can communicate with customers during fraud investigations while continuing to comply with the confidentiality requirements surrounding Suspicious Activity Reports (SARs).


On September 2, 2026, the Federal Reserve, Federal Deposit Insurance Corporation (FDIC), National Credit Union Administration (NCUA) and Office of the Comptroller of the Currency (OCC) issued a joint statement addressing the relationship between SAR confidentiality and customer communications.


The clarification is significant because financial institutions have long faced a practical challenge: they must protect the confidentiality of SARs, but they also need to communicate with customers when investigating potentially fraudulent or suspicious transactions.

The regulators' statement makes clear that these two obligations are not necessarily incompatible.


SAR confidentiality remains in place

Under the Bank Secrecy Act, financial institutions cannot disclose a SAR or information that would reveal that a SAR exists. This restriction also applies when the person receiving the information is the customer who is the subject of the report.


The confidentiality requirement serves an important law-enforcement purpose. Revealing the existence of a SAR could alert a potential suspect, interfere with an investigation, discourage financial institutions from reporting suspicious activity and potentially expose individuals involved in filing reports to risks.


However, the regulators emphasized an important distinction.


SAR confidentiality does not automatically extend to the underlying facts, transactions and documents that led to a SAR. Those underlying materials can, in appropriate circumstances, be discussed with customers and other relevant parties.


That distinction provides banks with considerably more room to communicate than a broad interpretation of SAR confidentiality might suggest.


Banks can discuss suspicious transactions with customers

The joint statement explains that banks can communicate with customers about potentially fraudulent or otherwise suspicious transactions involving their accounts, provided the communication does not reveal the existence of a SAR.


This means that a bank can investigate a transaction by asking the customer questions about what happened, why a payment was made or where money originated.


For example, a financial institution may ask a customer to explain the purpose of a transaction, provide supporting documentation or identify the source of funds.


Banks can also seek information about the person or entity that originated or received a transfer.


Such communications can form an important part of a fraud investigation. They allow institutions to establish the circumstances surrounding a transaction without necessarily disclosing whether a SAR has been filed or may be filed.


Account restrictions and closures can also be discussed

The regulators' clarification extends beyond questions about individual transactions.


Banks may communicate with customers concerning delays, limitations, restrictions or closures involving an account when those actions may be connected to suspected fraud or other suspicious activity.


This is particularly important for customers whose accounts have been restricted or closed and who may otherwise receive little explanation from their financial institution.


The regulators indicate that a bank can tell a customer that an account action may relate to suspected fraudulent or suspicious activity, so long as the communication does not disclose the existence of a SAR.


Similarly, a bank can communicate that a deposit has been rejected because of suspected fraud. The regulators specifically identify circumstances involving altered or counterfeit checks as an example.


The clarification therefore allows institutions to provide customers with meaningful information about the reason for certain operational decisions without crossing the line into disclosure of confidential SAR information.


Fraud warnings and customer education remain possible

The guidance also confirms that financial institutions can provide customers with warnings and educational information concerning fraud.


This includes discussions about fraud schemes and typologies, including money-mule arrangements.


That ability is particularly relevant as banks attempt to prevent customers from becoming victims of fraud or inadvertently participating in transactions involving illicit funds.


Customer education can also help institutions obtain useful information during an investigation. A customer who understands why a particular transaction has raised concerns may be better positioned to provide documentation or explain the circumstances surrounding it.


Banks can request due diligence information

The regulators also make clear that SAR confidentiality does not prevent institutions from obtaining information needed to conduct customer due diligence and develop an appropriate customer risk profile.


A bank may therefore request information or documentation from a customer when it needs to understand the customer's activities, transactions or sources of funds.


The underlying principle remains that the institution must be careful not to turn such communication into an indirect disclosure that a SAR has been filed.


Cyprus Company Formation

The distinction between facts and the SAR is critical

The central issue in the regulators' clarification is the distinction between information about the activity and information revealing the existence of a SAR.


A bank can generally discuss the facts surrounding a transaction, including questions about its purpose, source of funds, parties involved and related documentation.


What the bank cannot do is tell the customer that a SAR has been filed, disclose the SAR itself or provide information that would reveal its existence.


The distinction means that communications must be handled carefully. A statement that appears to discuss only a transaction could nevertheless become problematic if, in context, it effectively confirms that a SAR exists.


For that reason, the regulators emphasize that communications should be evaluated on a case-by-case basis and that banks should take precautions when discussing information that could reveal the existence of a SAR.


Communication with other financial institutions

The clarification is also relevant to communications between financial institutions.

The principles apply not only to conversations with the customer but also to communications concerning suspicious or potentially fraudulent activity involving other banks or credit unions.


This can be particularly important in fraud investigations involving multiple institutions.


Banks may need to exchange information concerning transactions and underlying facts while ensuring that SAR confidentiality remains protected.


The same basic boundary applies: institutions can communicate about relevant underlying activity, but they must not disclose a SAR or information that would reveal that one exists.


No new SAR rules have been created

Despite the practical importance of the clarification, regulators stressed that the statement does not create a new SAR confidentiality regime.


The joint statement does not change existing Bank Secrecy Act requirements or establish new supervisory expectations. Instead, it explains how existing confidentiality obligations should be understood when banks communicate with customers during fraud investigations.


The statement was prompted in part by concerns raised during a 2025 request for information concerning measures to address payments fraud, particularly check fraud.


Commenters had asked regulators to clarify how financial institutions could communicate openly with customers about potentially fraudulent activity while still complying with SAR confidentiality requirements.


The September 2026 statement responds to that concern by drawing a clearer line between protected SAR information and the underlying activity that prompted a bank's investigation.


Implications for compliance teams

For banks and credit unions, the clarification provides greater certainty for compliance, fraud and customer-service teams.


Institutions can review their existing procedures to determine whether employees have been overly restricted in communicating with customers about suspicious transactions.


At the same time, the guidance does not provide a blanket authorization for unrestricted disclosure. Employees must still understand the difference between discussing a transaction and revealing that the institution has filed—or may file—a SAR.


Training, customer-service scripts and escalation procedures may therefore need to distinguish clearly between permissible discussions of transaction facts and prohibited SAR disclosures.


The OCC has specifically noted that the joint statement applies to community banks as well as larger institutions.


A clearer balance between confidentiality and transparency

The regulators' message ultimately establishes a more practical balance between two competing objectives.


On one side is the need to preserve SAR confidentiality so that financial institutions can report suspicious activity without alerting potential subjects or compromising law-enforcement investigations.


On the other is the need for banks to communicate with customers when fraud is suspected, transactions are questioned or accounts are restricted or closed.


The September 2 statement makes clear that SAR confidentiality does not require banks to remain silent about the underlying circumstances.


Financial institutions can ask questions, request documentation, discuss suspicious transactions, provide fraud warnings and explain certain account decisions. What remains off limits is disclosure of the SAR itself or information that would reveal its existence.


For banks and their customers, the clarification could lead to more informative and transparent communications during fraud investigations while preserving the confidentiality protections at the heart of the SAR reporting system.


The regulators' position is therefore not a relaxation of SAR confidentiality, but a clarification of its boundaries: the report remains confidential, while the underlying facts and transactions may, when handled appropriately, be discussed. 

By fLEXI tEAM

Comments


bottom of page